The Quarterly Threat Landscape Report is out. See what attackers are targeting now.Read report

Vulnerability & Exploit Database

Rapid7’s curated database of vulnerabilities, featuring exploit modules and check methods integrated into the Metasploit Framework.

Emergent Threat6
CVE-2026-76461:Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
CVE-2026-85706:Critical GitLab Path Traversal Exploited in the Wild
CVE-2026-83548:Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
CVE-2026-81578:PaperCut NG/MF Critical Zero-Day Exploited in the Wild
CVE-2026-63520:Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
CVE-2026-19490:Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
TitleEitWModules
CVE-2024-11065: Improper Neutralization of Special Elements used in an OS Command7.2 HighN/A1%Nov 11, 2024
CVE-2024-11064: Improper Neutralization of Special Elements used in an OS Command7.2 HighN/A1%Nov 11, 2024
CVE-2024-11063: Improper Neutralization of Special Elements used in an OS Command7.2 HighN/A1%Nov 11, 2024
CVE-2024-11062: Improper Neutralization of Special Elements used in an OS Command7.2 HighN/A1%Nov 11, 2024
CVE-2024-48442: Missing Authentication for Critical Function6.5 MediumN/A0%Oct 24, 2024
CVE-2024-20526: Uncontrolled Resource Consumption5.3 MediumN/A0%Oct 23, 2024
CVE-2024-20481: Missing Release of Resource after Effective Lifetime5.8 MediumN/A16%Oct 23, 2024
CVE-2024-20329: Improper Neutralization of Expression/Command Delimiters9.9 CriticalN/A1%Oct 23, 2024
CVE-2024-10100: Improper Limitation of a Pathname to a Restricted Directory7.5 HighN/A1%Oct 17, 2024
CVE-2023-32189: Authorization Bypass Through User-Controlled Key5.9 Medium6.4 Medium0%Oct 16, 2024
CVE-2023-37154: Improper Neutralization of Special Elements used in a Command8.4 HighN/A0%Oct 9, 2024
CVE-2024-38029: External Control of File Name or Path7.5 HighN/A1%Oct 8, 2024
CVE-2024-43615: External Control of File Name or Path7.1 HighN/A1%Oct 8, 2024
CVE-2024-43581: External Control of File Name or Path7.1 HighN/A1%Oct 8, 2024
CVE-2024-28813: Improper Privilege Management8.4 HighN/A0%Sep 30, 2024
CVE-2024-28812: Use of Hard-coded Credentials8.8 HighN/A0%Sep 30, 2024
CVE-2024-6394: Path Traversal: '\..\filename'7.5 HighN/A1%Sep 30, 2024
CVE-2024-8451: Uncontrolled Resource Consumption7.5 HighN/A1%Sep 30, 2024
CVE-2024-7594: Incorrect Permission Assignment for Critical Resource7.5 HighN/A0%Sep 26, 2024
CVE-2024-47179: Improper Input Validation8.8 HighN/A1%Sep 26, 2024
CVE-2024-20350: Use of Hard-coded Cryptographic Key7.5 HighN/A0%Sep 25, 2024
CVE-2023-25189: Incorrect Authorization3.3 LowN/A0%Sep 25, 2024
CVE-2024-8281: Improper Neutralization of Special Elements used in an OS Command7.2 HighN/A1%Sep 13, 2024
CVE-2024-45030: Out-of-bounds Write9.8 CriticalN/A0%Sep 11, 2024
CVE-2024-43798: Missing Authentication for Critical Function8.6 HighN/A0%Aug 26, 2024
701-725 of 1962